All lessons Leer en español

Security in depth · Unit 30 · Lesson 3 of 11

Separate observation from inference

Report a broad permission without claiming that somebody used it.

4 minreadyShort lesson

Helpful before thisReporting: turn evidence into useful improvements

See all lessons in this topic

After this lesson you can

  • Distinguish a confirmed configuration deviation from an unobserved access outcome.

A permission, a possible consequence, and a recorded action are different evidence.

Name the step beyond observation

An observation states what the supplied evidence directly shows. An inference interprets that evidence under assumptions. Reports need both, but readers must be able to tell where the reasoning moves beyond the observed record.

Assume a fictional archive’s approved storage policy permits Finance to read a confidential folder and prohibits grants to Reviewers. This is a configuration review, with no supplied access experiment or historical usage record. Other application restrictions are outside the packet.

Direct observation → Explicit interpretation → Qualified conclusionDirect observationExplicit interpretationQualified conclusion
The interpretation must be distinguishable from the observation. A qualified conclusion preserves assumptions and missing evidence.

Supplied review packet

  • O1: The approved policy names Finance as the only group that should receive the folder’s read grant.
  • O2: A dated configuration snapshot grants read to both Finance and Reviewers.
  • O3: No access history, current group-membership record, or assessment of additional application controls is supplied.

Write the strongest supported claim

O1 and O2 establish a configuration deviation: Reviewers has a grant the policy prohibits. O3 does not erase that mismatch. It limits claims about who could effectively access the folder and whether anyone actually did so.

The potential consequence is access beyond the intended audience if the relevant identity and other access conditions permit it. Label that condition explicitly. Avoid converting a configured permission into “documents were disclosed” or “every reviewer has read the files.”

Request the missing access context only if it is needed to assess exposure or incident history. Keep the original snapshot’s date so later permission changes do not silently rewrite the finding’s evidence.

Model wording: The snapshot grants Reviewers read contrary to policy. Potential exposure requires further access context; historical use was not established.

Terms you met

Inference

Check yourself

No timer. No penalties. Read the explanation and try again whenever you like.

  1. Which finding is supported by O1-O3?

    Show the answer

    Correct answer: The configured grant exceeds the stated policy; actual use and effective access remain unverified. The snapshot and policy establish the configuration mismatch. They do not show a completed access or every additional control.

Try it

  • WriteWrite a finding in three sentences: observed configuration, policy comparison, and potential consequence with a limit. Model the limit as historical use and effective access not established by this snapshot.
References